Description
Oracle E-Business Suite could allow a remote attacker to execute arbitrary code on the system, caused by a deserialization flaw in iesRuntimeServlet endpoint. By using specially-crafted serialized data, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Oracle E-Business Suite